Kaspersky believes that in a "widespread" attack, Chinese hackers installed a backdoor into Daemon Tools
  • Elena
  • May 05, 2026

Kaspersky believes that in a "widespread" attack, Chinese hackers installed a backdoor into Daemon Tools

Security researchers at Kaspersky have discovered a malicious backdoor in Daemon Tools, a widely used Windows application.

According to Kaspersky, the attack is “widespread” and has already affected thousands of computers. The hackers used the backdoor to install additional malware on targeted systems across retail, scientific, manufacturing, and government sectors.

The attack appears to be highly targeted, with affected organizations located in Russia, Belarus, and Thailand. Researchers believe the hackers are linked to a Chinese-speaking group based on the malware analysis.

Kaspersky first detected the backdoor on April 8 and has warned that the supply chain attack is still ongoing. This means attackers may continue to spread malware through the compromised software.

The issue highlights a growing trend of supply chain attacks, where hackers compromise popular software to infect many users at once. Earlier incidents have involved tools like Notepad++ and utilities from CPUID.

The developer of Daemon Tools, Disc Soft, said it is aware of the issue and is currently investigating but has not confirmed full details yet.